๐Ÿ” CVE Alert

CVE-2026-53459

UNKNOWN 0.0

Bambuddy's authentication fails open on database errors, allowing unauthenticated access to all endpoints

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Bambuddy is a self-hosted print archive and management system for Bambu Lab 3D printers. Starting in version 0.1.6 and prior to version 0.2.4.4, a fail-open in the authentication code allows any attacker to bypass authentication by flooding a public endpoint to exhaust resources causing database access to fail, granting unauthenticated access to all protected endpoints. Version 0.2.4.4 patches the issue.

CWE CWE-636 CWE-755
Vendor maziggy
Product bambuddy
Published Sep 15, 2026
Stay Ahead of the Next One

Get instant alerts for maziggy bambuddy

Be the first to know when new unknown vulnerabilities affecting maziggy bambuddy are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

maziggy / bambuddy
>= 0.1.6, < 0.2.4.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/maziggy/bambuddy/security/advisories/GHSA-6mf4-q26m-47pv github.com: https://github.com/maziggy/bambuddy/commit/845ad39b19bf99afeea571c6bae09695777e1460 github.com: https://github.com/maziggy/bambuddy/blob/449502cc9fc1cec04f06d31512420eac729fd032/backend/app/core/auth.py#L473-L483 github.com: https://github.com/maziggy/bambuddy/blob/449502cc9fc1cec04f06d31512420eac729fd032/backend/app/main.py#L5314-L5316 github.com: https://github.com/maziggy/bambuddy/blob/main/CHANGELOG.md github.com: https://github.com/maziggy/bambuddy/releases/tag/v0.2.4.4